Federal prosecutors allege that a mergers-and-acquisitions lawyer spent roughly a decade funneling his own clients’ deal secrets to a network of traders, generating tens of millions of dollars in illegal profits across nearly 30 transactions. The indictment in United States v. Nourafchan et al., filed April 28, 2026, in the District of Massachusetts, names the lawyer and co-defendants who allegedly used encrypted apps, coded language, and cash hand-offs to hide the scheme. The SEC brought a parallel civil action against 21 individuals, while the U.S. Attorney’s Office charged 30 people in total, creating a split that itself raises questions about how broadly the ring extended.
Why the Nourafchan insider-trading case matters right now
The gap between the two charging actions tells a story about scale. The SEC’s civil complaint, described in a recent litigation release, names 21 defendants, including Nourafchan and Yadgarov, and focuses on misappropriated M&A information from law firms. The DOJ’s criminal announcement, by contrast, describes 30 individuals charged in what it calls a global scheme netting tens of millions in illicit profits. That nine-person difference suggests additional participants face criminal exposure beyond the civil case, though the public filings do not fully explain the discrepancy.
The practical tension is straightforward: if one lawyer at a firm handling sensitive deal work can quietly pass material nonpublic information for a decade without detection, the controls that law firms, compliance departments, and regulators rely on failed repeatedly. Every public company that retained those firms during the alleged period now faces the question of whether its confidential deal terms were compromised. The case also lands amid heightened scrutiny of professional gatekeepers-lawyers, accountants, and bankers-who sit closest to corporate secrets and are expected to police, not exploit, that access.
For in-house counsel and boards, the allegations function as a stress test of existing insider-trading controls. Standard tools-restricted lists, wall-crossing procedures, and email surveillance-are designed around electronic footprints and firm systems. The Nourafchan indictment instead sketches a scheme that allegedly pushed communication and payment channels into spaces that corporate compliance teams rarely see, underscoring the limits of traditional monitoring.
Encrypted apps, cash, and coded language in the alleged scheme
The criminal indictment, filed in the District of Massachusetts, describes a concealment apparatus built to avoid the surveillance systems that typically catch insider trading. According to the charging document, defendants allegedly communicated through encrypted messaging platforms and used coded language to discuss upcoming deals. Phrases that appeared innocuous on their face allegedly served as signals about timing or targets of pending transactions.
Profits were allegedly moved through cash transfers and routed through nominee accounts and other people’s names to obscure the money trail. Prosecutors say some participants accepted envelopes of cash or engaged in back-and-forth transfers designed to make the proceeds look like personal loans or informal investments. When questioned, defendants allegedly created sham explanations for the transfers, including fabricated consulting arrangements and personal debts, to distance the payments from trading activity.
One specific example cited in the prosecution’s public narrative involves the alleged viewing of confidential iRobot materials while the lawyer was on leave from his firm. That detail, drawn from the U.S. Attorney’s Office press release, points to a pattern where access to deal documents allegedly continued even outside normal work periods. The indictment does not reproduce the encrypted messages themselves, but prosecutors describe their contents in summary form, emphasizing that the communications were calibrated to minimize explicit references to securities or issuers.
The SEC’s civil action echoes these allegations but frames them around the securities law violations rather than the criminal concealment charges. The regulator’s public statement describes a wide-reaching insider trading scheme in which M&A information was misappropriated from law firms and passed to traders who executed pre-announcement trades. The complaint alleges that the traders often concentrated positions in options or leveraged instruments, magnifying gains when deals became public.
What the public record does not yet show
Several pieces of the case remain out of public view. The exact names of the law firms that employed the alleged leaker do not appear in the charging documents, which instead refer to them generically. That omission is typical in early-stage filings but leaves clients and counterparties guessing whether their own transactions may have been touched by the scheme. The filings also do not fully map the alleged flow of information from the lawyer to the outer edges of the trading network, beyond high-level descriptions of “tippees” and downstream traders.
Another open question is how, and when, the activity was first detected. The public materials do not spell out whether the investigation began with suspicious trading alerts, a whistleblower tip, or cooperation from one of the charged individuals. The answer matters for compliance officers trying to assess which detection tools actually worked in this instance and which failed to spot a decade-long pattern.
Finally, the discrepancy between the 21 civil defendants and 30 criminal defendants hints at investigative threads that have not yet been fully disclosed. Some individuals may face only criminal charges; others may be cooperating or awaiting additional filings. Until more details surface through arraignments, plea negotiations, or trial, outside observers will have to read between the lines of the current record to understand how extensive the alleged network really was-and how many similar schemes may still be operating just beyond the reach of existing controls.



